Vulnerability record · CVE-2018-1323 · published 12 March 2018
CVE-2018-1323: Apache Tomcat JK ISAPI Connector path normalization bypass exposes hidden apps
Apache · Tomcat Jk Connector
The IIS/ISAPI-specific code in Apache Tomcat JK ISAPI Connector 1.2.0 through 1.2.42 normalized request paths before matching them to the URI-worker map and mishandled some edge cases. When only a subset of Tomcat URLs was exposed through IIS, a crafted request could reach application functionality not intended to be reachable through the reverse proxy.
Description
The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the reverse proxy.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with network reachability and no authentication required, plus a high EPSS percentile, makes this a serious exposure risk despite no confirmed in-the-wild exploitation.
What it is
The IIS/ISAPI-specific code in Apache Tomcat JK ISAPI Connector 1.2.0 through 1.2.42 normalized request paths before matching them to the URI-worker map and mishandled some edge cases. When only a subset of Tomcat URLs was exposed through IIS, a crafted request could reach application functionality not intended to be reachable through the reverse proxy.
Impact
An unauthenticated remote attacker can bypass the intended reverse-proxy URL restrictions and reach Tomcat application endpoints that were meant to be hidden, gaining access to functionality or data behind the proxy.
Attack surface
Reached over the network via HTTP requests to an IIS server fronting Tomcat with the JK ISAPI Connector; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.46397 (98.8th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade the Apache Tomcat JK ISAPI Connector to a version later than 1.2.42 that contains the fix.
- Apply vendor errata such as Red Hat RHSA-2018:1843 where the connector is packaged.
- Review and tighten the URI-worker map so only explicitly required Tomcat URLs are proxied.
- Restrict network access to the IIS/ISAPI front end so only trusted clients can reach it.
Detection
- Inspect IIS and JK connector logs for requests containing encoded or unusual path sequences (e.g., %2e, %2f, double slashes) that resolve to non-exposed URIs.
- Baseline the set of URIs normally served through the connector and alert on requests to paths outside that baseline.
- Monitor for HTTP requests reaching Tomcat application endpoints that are not in the intended exposed URL list.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-1323 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1323), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.